CAREER: Taming the size, complexity and longevity of OS kernels via enhanced OS kernel extensions
CAREER: Taming the size, complexity and longevity of OS kernels via enhanced OS kernel extensions
批准号:
2236966
负责人:
Daniel Williams
金额:
$60.27万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2023
资助国家:
美国
项目状态:
未结题
起止时间:
2023-05-01 至 2028-04-30
中文摘要
操作系统(OS)内核是社会所依赖的最基本的软件组件,支撑着计算行业,从管理我们数据的云和数据中心到我们日常使用的智能手机和其他设备。 不幸的是,它们已经变得越来越复杂,并且没有跟上编程语言和模块化软件设计的进步,而是努力应对我们计算基础设施的现代安全性和可靠性威胁。 此外,似乎没有明确的路径来逐步发展它们,它们未经检查的复杂性已经成为学生和从业者在内核级别学习或创新的重要障碍。 这个项目试图通过在遗留的OS内核中创建一个安全的内核扩展框架来解决这个问题,使其能够部分或全部被安全组件取代。 通过这个扩展框架,本项目将为本科生、研究生和从业人员提供一个实用的、可逐步采用的机制,使内核更安全、更可靠,提高国家安全,为社会和国民经济带来更高的生产力。本项目旨在实现OS内核的三个目标:通过语言安全实现安全性和健壮性,通过组件化实现健壮性和增量更新,以及通过构建现有内核扩展框架实现实用性。在我们的方法中的关键见解是,一个安全的内核扩展框架可以在遗留的操作系统内核中创建,使它的任何部分都可以通过旁路扩展,朝着安全的,组件化的体系结构发展内核,或者在其整体上具有安全和专门的原位内核。 我们的综合研究和教育计划涉及三个广泛的研究重点。首先,我们将探讨内核扩展的可表达性/安全性权衡,并将设计一个新的基于Rust的内核扩展环境,该环境提供了比Linux中流行的eBPF内核扩展框架更具表达性的编程环境类似的安全保证。其次,我们将探索我们增强的安全内核扩展在多大程度上可以用旁路扩展替换单个内核组件,并探索Linux中新的组件边界。最后,我们将探索在多大程度上可以从扩展创建全新的原位内核,最终在Linux的上下文中。 我们的教育计划整合了课程研究和其他涉及开源和行业的举措。该奖项反映了NSF的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Operating system (OS) kernels are the most fundamental softwarecomponent society depends on, underpinning the computing industry,from the clouds and datacenters that manage our data to the smartphones and other devices we all use daily. Unfortunately, they havegrown to be complex and have not kept pace with advances inprogramming languages and modular software design, instead strugglingto meet modern security and reliability threats to our computinginfrastructure. Moreover, there appears to be no clear path toincrementally evolve them and their unchecked complexity has become asignificant barrier to entry for students and practitioners to learnor innovate at the kernel level. This project seeks to remedy thisissue by create a safe kernel extension framework within the legacy OSkernel that enables it to be replaced in part or in its entirety withsafe components. Through this extension framework, the project willenable a practical, incrementally-adoptable mechanism forundergraduate, graduate students and practitioners to evolve kernelsto be safer and more reliable, improving national security and leadingto higher productivity for society and the national economy.This project aims to achieve three goals for the OS kernel: securityand robustness through language safety, robustness and incrementalupdate through componentization, and practical relevance throughbuilding upon existing kernel extension frameworks. The key insight inour approach is that a safe kernel extension framework can be createdwithin the legacy OS kernel that enables any part of it to be replacedvia bypass extensions, evolving the kernel towards a safe,componentized architecture, or in its entirety with a safe andspecialized in-situ kernel. Our integrated research and educationplan involves three broad research thrusts. First, we will exploreexpressiveness/safety tradeoffs for kernel extensions, and will designa new Rust-based kernel extension environment that provides similarsafety guarantees with a more expressive programming environment thanthe popular eBPF kernel extension framework in Linux. Second, we willexplore to what extent our enhanced safe kernel extensions can replaceindividual kernel components with bypass extensions and explore newcomponent boundaries in Linux. Finally, we will explore to what extentan entirely new in-situ kernel can be created from extensions,ultimately in the context of Linux. Our educational plan integratesthe research in courses and other initiatives involving open sourceand industry.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(3)
专著(0)
科研奖励(0)
会议论文
Enabling eBPF on Embedded Systems Through Decoupled Verification
通过解耦验证在嵌入式系统上启用 eBPF
DOI:
10.1145/3609021.3609299
发表时间:
2023
期刊:
ACM
影响因子:
--
作者:
[Craun, Milo, Oswald, Adam, Williams, Dan]
通讯作者:
Williams, Dan
Enabling BPF Runtime policies for better BPF management
启用 BPF 运行时策略以更好地管理 BPF
DOI:
10.1145/3609021.3609297
发表时间:
2023
期刊:
ACM
影响因子:
--
作者:
[Sahu, Raj, Williams, Dan]
通讯作者:
Williams, Dan
Kernel extension verification is untenable
内核扩展验证站不住脚
DOI:
10.1145/3593856.3595892
发表时间:
2023
期刊:
ACM
影响因子:
--
作者:
[Jia, Jinghao, Sahu, Raj, Oswald, Adam, Williams, Dan, Le, Michael V., Xu, Tianyin]
通讯作者:
Xu, Tianyin
Mathematical Sciences: NSF-CBMS Conference on Multivariate Splines, August 1987
-
批准号:8619409
-
项目类别:Standard Grant
-
资助金额:$2.36万
-
财政年份:1987
-
负责人:Daniel Williams
-
依托单位:
海外基金